Benign Download

Trojan-PSW.Win32.QQPass.bwj

Detects an XORed URL in an executable
SHA-256b2934e9569bf5a3448c205d63aebb8d7849556a997c0194e128a81dc75dfa367
MaleculeTh

Evidence

Detects an XORed URL in an executable 0x6b24–0x6be4
⋯3 more rows
0x6b546341646472657373003b3f3e353f3d2acAddress.;?>5?=*
0x6b646478787c3623237b7b7b227d64766d65dxx|6##{{{"}dvme
0x6b7474656d62226f62235d5d226d7f7c2a79temb"ob#]]"m.|*y
⋯7 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.